SESSIONSCONFERENCESABOUT USCONTACT
SIGN IN

Legal

Privacy Policy

Effective August 3, 2026

This is the plain-English version of what we do with your personal data, and it is also the formal notice we are required to give you under the UK GDPR. We have tried to make it readable, because a lot of the people using Gavelling are still at school.

The short version: we collect what we need to run committee sessions and conference applications, we do not sell anything to anyone, session data is deleted 72 hours after a session ends, and you can ask us to show you or delete what we hold. Your rights are in section 07.

01

Who we are

Gavelling is a Model United Nations conference and committee platform at gavelling.com. It is operated by GAVELLING LTD, a private limited company registered in England & Wales under company number 17337652, whose registered office is Flat 33 Doughty Court, Prusom Street, London, England, E1W 3RT.

In this policy, "we", "us" and "our" mean GAVELLING LTD. For most of the data described here, GAVELLING LTD is the data controller — the organisation that decides what is collected and why. Section 02 explains the one important exception.

We do not currently have a statutory Data Protection Officer. Data protection questions go straight to the people who build the product: wearegavelling@gmail.com.

Gavelling is independent and is not affiliated with or endorsed by the United Nations.

02

Who controls your data — us, or the conference organiser

This split matters, because it changes who you ask when you want something done.

  • Your account is ours. Your login, profile, MUN CV, saved preferences and any payments you make to us — GAVELLING LTD is the controller. Ask us.
  • A conference's applicant data is theirs. When you apply to a conference listed on Gavelling, the organiser is the controller of your application: the answers to their custom questions, your committee and country preferences, your position papers, your allocation, and their notes on you. We act as their processor — we store and move that data on their documented instructions and do not use it for our own purposes.

So if you want an application deleted, corrected, or explained, contact the organising team of that conference first — they are the ones who decide. Email us anyway if you get stuck. We will help you find the right contact, and we will act on a valid instruction from the organiser without dragging it out. This mirrors section 7 of our Terms of Service.

03

What we collect

Gavelling has two products, and they collect very different amounts of data. Open whichever applies to you.

04

Why we use it, and our lawful basis

UK GDPR says we need a legal reason — a "lawful basis" — for every purpose. Here is ours, purpose by purpose.

Running committee sessionsContract — Art 6(1)(b)

Showing the speakers list, timers, motions, documents and chat to everyone in the room is the service you asked for.

Creating and running your accountContract — Art 6(1)(b)

Signing you in, showing your profile, your conferences and your CV.

Handling conference applications and allocationsProcessor — on the organiser's instructions

The organiser is the controller here and sets their own lawful basis; we process on their behalf. See section 02.

Taking payments, credits and subscriptionsContract — Art 6(1)(b)

Processing what you buy and giving you access to it.

Service emails you cannot turn offContract — Art 6(1)(b)

Password resets, payment receipts, application status. These are part of the service, not marketing.

Keeping financial and accounting recordsLegal obligation — Art 6(1)(c)

UK tax and company law requires us to keep records of what we were paid.

Responding to legal requests and court ordersLegal obligation — Art 6(1)(c)
Security, abuse and fraud preventionLegitimate interests — Art 6(1)(f)

Our interest: keeping the platform, and the many under-18s on it, safe from abuse, impersonation, spam and fraudulent payments. We think you would expect us to do this.

Crash diagnostics and bug fixingLegitimate interests — Art 6(1)(f)

Our interest: a live committee session cannot wait for a fix, so we want to know the moment something breaks.

Improving the productLegitimate interests — Art 6(1)(f)

Our interest: understanding which features are actually used, so we build the right things. We use aggregate patterns, not individual profiling.

Answering your support messagesLegitimate interests — Art 6(1)(f)

Our interest: replying to a person who has contacted us for help.

Marketing and announcement emailsConsent — Art 6(1)(a)

Opt in, and opt out whenever you like. See section 12.

Publishing your MUN CV as a public pageContract — Art 6(1)(b)

Every account has a public CV page and there is currently no way to turn it off. Read section 16 before you add anything to it.

Optional (non-essential) cookies and storageConsent — Art 6(1)(a) and PECR

Essential storage that makes the app work does not need consent; anything beyond it does.

Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms. You can object to any of it — see section 07 — and we will stop unless we have compelling grounds not to.

05

Special category data

"Special category" data is the extra-sensitive kind under Article 9 — health, race or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic and biometric data.

We do not ask for any of it, and we do not intentionally collect it. Nothing on Gavelling requires you to disclose it. Nationality, and the country you are assigned to represent in committee, are roles and identifiers rather than Article 9 data.

The one risk is free text. Bios, position papers, application answers, chat messages and CV descriptions are boxes you can type anything into. Please do not put health details, religious or political beliefs, or anything similarly sensitive into them — not about yourself, and definitely not about anyone else. If you do, we will hold it simply because you typed it, and we would rather you did not.

Debating a political topic in committee is not the same thing as disclosing your own political beliefs, and we do not treat committee positions as a record of what you personally think.

06

Young people

Model UN is run in schools, so we know a large share of the people reading this are under 18. We have tried to design for that rather than pretend otherwise.

  • You must be 13 or older to create a Gavelling account.
  • If you are under 18, use Gavelling with the knowledge and permission of a parent, guardian, teacher or faculty advisor.
  • Joining a session as a delegate does not require an account or an email address, so a school can run a committee without any pupil handing over personal details.
  • Where a school or conference enters a young person's details for them, that organiser is responsible for having the right permission to do so.

We take the ICO's Age Appropriate Design Code seriously: we collect the minimum we need, we do not profile children, we do not use nudge techniques to push anyone into sharing more, nothing is made public by default, and session data deletes itself on a short clock.

If you are a parent, guardian or teacherand you want a young person's data removed, email wearegavelling@gmail.com. You do not need to quote legislation at us or explain yourself at length — tell us the account email or the session code and we will sort it out. If the data sits with a conference organiser we will tell you who they are and help you reach them.

If you are under 13 and have made an account anyway, that is alright — just email us, or ask an adult to, and we will delete it. Nobody is in trouble.

07

Your rights

These are yours under the UK GDPR. They are free to use, and asking us to use one will never count against you.

Access. Get a copy of the personal data we hold about you, and an explanation of what we do with it.

Email us. Much of it is already visible in your account.

Rectification. Have anything inaccurate corrected, or anything incomplete filled in.

Edit it yourself in Account → Profile, or email us for anything you cannot reach.

Erasure. Have your data deleted — the 'right to be forgotten'.

Delete your account in Account → Profile, which removes your profile, CV and preferences. Or email us. We may keep the minimum required for tax and accounting records (section 10).

Restriction. Tell us to keep your data but stop using it, for example while you dispute whether it is accurate.

Email us and say what you want paused.

Portability. Receive the data you gave us in a common, machine-readable format, or have us send it to another service where technically possible.

Email us and we will export it.

Objection. Object to processing we base on legitimate interests, and object to direct marketing at any time — marketing objections are absolute, we must stop.

Email us, or switch the relevant emails off in Account → Profile.

Withdrawing consent. Where we rely on your consent, you can take it back at any time. That does not make what we did beforehand unlawful.

Turn off email preferences in Account → Profile, unpublish your CV (section 16), or email us.

Not being subject to solely automated decisions. You have the right not to be subject to a decision based only on automated processing that has a legal or similarly significant effect on you.

We do not make decisions that way — see section 15 — but you can always ask a human to look again.

How to use any of them: email wearegavelling@gmail.com from the address on your account if you can, or tell us enough to find you (for session data, the session code). We will respond within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you why within the first month. We may need to check who you are before handing over personal data.

For anything a conference organiser controls — your application, allocation or their notes — the organiser has to make the decision. Contact them first, and copy us in if you would like us to chase it.

08

Who else handles your data

We do not sell, rent or trade personal data. We use a small set of service providers who process it on our instructions:

  • Supabase — database, authentication, file storage and server-side functions. Most of what Gavelling stores lives here.
  • Vercel — hosting and content delivery for the website itself.
  • Stripe — payment processing. Card details go to Stripe, not to us.
  • Resend — sending transactional and announcement emails.

Each of them is bound by a contract that limits them to processing data for us. Beyond that, data goes to a conference organiser only when you apply to their conference, and to the other people in your committee only where the session is designed to show it (your name in the speakers list, a paper you submitted, a message you sent).

We may also disclose data where the law requires it, or where it is necessary to protect the rights and safety of our users — particularly the young people using the platform.

09

Sending data outside the UK

Our infrastructure providers — Supabase, Vercel and Stripe — are US-based, and our database is hosted in a US region. That makes these restricted transfers under UK data protection law, so they need a safeguard.

For each provider we rely on one of the following mechanisms:

  • the UK Extension to the EU–US Data Privacy Framework, where that provider is certified under it; or
  • the ICO's International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.

We are deliberately not claiming here that a particular provider holds a particular certification, because certifications change and we will not assert one we have not re-checked. If you want to know exactly which mechanism applies to which provider today, email wearegavelling@gmail.com and we will tell you what is in place at that moment.

10

How long we keep things

Live session data72 hours after the session ends

Speakers lists, chat, documents, motions, votes and speaking history are deleted automatically once a session is ended.

Sessions that were never formally endedPurged periodically

Abandoned sessions are cleaned up on a rolling basis.

Account and profileUntil you delete your account

Delete the account and the profile, CV and preferences go with it.

Conference applications and allocationsAs long as the organiser needs them

The organiser decides, because they are the controller. Ask them, and we will act on their instruction.

Payment and financial recordsAbout 6 years

UK tax and company law requires us to keep accounting records for six years after the end of the relevant accounting period.

Crash reports and error logsOnly while we need them

Kept long enough to diagnose and fix the bug, then cleared.

Data in your browserUntil you clear it

Local storage stays on your device until you clear your browser storage or sign out.

After deletion, copies can survive briefly in routine encrypted backups before those backups roll over. We do not restore deleted data from a backup to bring it back.

11

Cookies and local storage

Gavelling leans on your browser's localStorage more than on cookies. Either way, here is the honest split.

Essential — the app does not work without these:

  • Authentication tokens stored by Supabase Auth, so you stay signed in between page loads.
  • Session and committee state — the code you last joined, your committee settings, chat read counts, and the local copy of the committee the app renders from.
  • Preferences such as your language choice.
  • Strictly necessary cookies our hosting provider sets for infrastructure and security.

Optional:

We do not currently run advertising cookies, third-party analytics or tracking pixels. If that ever changes we will ask for your consent first, and you will be able to say no and keep using Gavelling.

You can clear local storage and cookies from your browser settings at any time. Doing so signs you out and forgets your local preferences; it does not delete anything held on our servers.

12

Emails you get from us

  • Service emails — password resets, payment receipts, application updates, and messages from a conference you applied to about that conference. These are part of the service, so you cannot switch them off while you have an account.
  • Announcements and marketing — these go only to people who have opted in, and every one of them can be turned off in Account → Profile. Organisers sending a broadcast through Gavelling cannot reach anyone who has opted out; we exclude them automatically.

Emails are delivered by Resend on our behalf. We never sell your email address or pass it to anyone for their own marketing.

13

Security

Concretely, and without overselling it:

  • Everything travels over encrypted connections (HTTPS/TLS).
  • Data is protected at the database layer by row-level security policies, so a request can only reach the rows it is entitled to — not just the screens the app chooses to show.
  • Passwords are hashed by Supabase Auth. We cannot see them, and neither can anyone who reads our database.
  • Card details never reach us. Stripe takes them directly.
  • Access to production data is limited to the people who need it to run the service.
  • Session codes act as access keys — share a code only with the people who should be in that committee.

We are a small team and we hold no security certifications. No service on the internet can promise perfect security, and we are not going to pretend otherwise. What we can promise is that we take it seriously and that we will tell you the truth if something goes wrong.

14

If there is a data breach

If personal data we hold is lost, exposed or accessed without permission, and there is a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware of it, as the law requires.

Where a breach is likely to result in a high risk to you, we will tell you directly and without undue delay — what happened, what data was involved, what we are doing about it, and what you should do. Where a conference organiser is the controller, we will notify them so they can meet their own obligations.

15

Automated decision-making

Gavelling can suggest committee and country allocations to an organiser based on the preferences and information applicants have submitted. That is a suggestion on a screen, and nothing more.

A human organiser always makes the final decision, and can override any suggestion. So there is no decision on Gavelling based solely on automated processing that produces legal effects for you or similarly significantly affects you, and we do no profiling for advertising or any other purpose.

If you think an allocation decision was made unfairly, raise it with the conference organiser — it was their call, not an algorithm's.

16

Your MUN CV is public

Every account has an MUN CV, and it is a public page at gavelling.com/cv/your-name-1a2b3c4d. Anyone who has that address can open it without signing in and without an account. It is public from the moment your account exists — you do not have to publish it, and there is nothing to switch on.

There is currently no way to make it private. We have no visibility setting, no unlisted mode and no opt-out. If that matters to you, the practical control you have is what you put on it — see below.

What a visitor sees: your display name, profile photo, nationality, education level, MUN experience level, bio, and the CV entries on your record — conference names, committees, allocations, awards, dates, and any photos or descriptions you added to an entry. Your email address is not on the page, and neither is your date of birth, your applications, or anything you have paid.

Who ends up looking at it. Your name links to this page throughout the organiser tools — so the organisers of any conference you apply to, and the leaders of a delegation you belong to, can open it while they are reviewing you. Beyond that, it is the link you choose to share. We do not submit CVs to search engines, but we also do not block crawlers from them, so a CV linked to from a public page can be indexed. Once a link is out in the world you cannot control who passes it on.

To take something down: delete the individual entry in Account → MUN CV and it disappears from the public page immediately. Emptying your CV leaves a page with your name and photo on it and nothing else; deleting your account removes the page entirely. A copy somebody has already saved is out of our hands either way.

If you are under 18, read this section again before you add anything. Nothing on Gavelling works less well if your CV stays empty, and an empty CV is the only version of "private" we can offer you today.

17

Changes to this policy

Gavelling is still growing, so this policy will change. When it does we will update the effective date at the top of the page.

For anything significant — a new purpose, a new category of data, a new provider handling your data — we will tell you properly in the app or by email before it takes effect, rather than quietly editing this page. If a change relies on your consent, we will ask you for it.

18

Complaints and contact

If you are unhappy with how we have handled your data, tell us first — we would like the chance to put it right, and it is usually the fastest route.

GAVELLING LTD
Flat 33 Doughty Court, Prusom Street, London, England, E1W 3RT
Registered in England & Wales no. 17337652
wearegavelling@gmail.com

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO). You can do that whether or not you come to us first — you do not need our permission and you do not have to wait for our reply.

  • Online: ico.org.uk
  • Helpline: 0303 123 1113
  • By post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

For questions about the rules of using Gavelling rather than your data, see our Terms of Service.